The README is brief and explicitly leaves documentation unfinished; the repository also has no security policy or scanning. Organizational backing and a stable version provide some reassurance, but not enough to offset the age of the release.
42%
Total Score
50
75
50
The latest release was in 2017, with no releases in the last 12 months and only two releases overall. That long release gap is a substantial maintenance concern for a deployment package.
The repository recorded zero commits and zero active maintainers in the last three months, consistent with the release history showing prolonged inactivity.
A README is present, but it is only 193 characters and explicitly says documentation is still a TODO. Tests and changelog absence are normal for a published deployment artifact, so they do not add concern.
Composer is used as a build tool, which is positive, but no security-scanning tooling is present. That weakens ongoing supply-chain and dependency oversight.
The repository has no security policy, leaving no documented route for reporting vulnerabilities or explaining security practices. This is a transparency gap, though it is less serious than the inactivity evidence.
We didn't find any vulnerabilities for this package.
| Dependency | Last Release | Score |
|---|---|---|
neam/docker-stack Version *@dev | — | — |
neam/php-app-config Version *@dev | — | — |
neam/yii-dna-test-framework Version *@dev | — | — |
neam/docker-diff-based-layers Version *@dev | — | — |
neam/yii-dna-pre-release-testing Version *@dev | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.